oidc-client-ts无法返回完整Profile Claims问题求助
我使用 oidc-client-ts(TypeScript 版本)实例化 UserManager 时采用如下配置:
var config = { authority: "https://localhost:3000", client_id: "js", redirect_uri: "https://localhost:3001/callback.html", response_type: "code", scope: "openid profile IdentityServerApi colour", post_logout_redirect_uri: "https://localhost:3001/index.html", }
调用 usermanager.getUser() 返回的 user 对象,其 profile claims 仅包含以下字段:
{ "iss": "https://localhost:3000", "iat": 1681658331, "exp": 1681658631, "aud": "js", "sid": "E5E4621779C8970433CEE2E6472FF8DE", "sub": "cc23a1a1-a8ff-4caf-8fef-555d98923b8a", "idp": "local" }
但使用相同配置的 oidc-client-js 返回的 profile 包含更多字段:
{ "amr": [ "pwd" ], "sid": "32A90BF8B0EBF7780BC9B8E0AD3DDE8B", "sub": "cc23a1a1-a8ff-4caf-8fef-555d98923b8a", "auth_time": 1681659272, "idp": "local", "name": "theadmin@email.com", "preferred_username": "theadmin@email.com", "favorite_colour": "FAVORITECOLOUR_DEFAULT" }
我尝试在配置中添加 client_authentication、loadUserInfo 等参数,但无效果。授权端点显示,使用 ts 模块时 userClaims 会被请求两次,而 js 模块会请求三次。客户端回调页的 UserManager 配置如下:
{ authority: "https://localhost:3000", response_mode: "query", client_id: "js", redirect_uri: "https://localhost:3001/callback.html", }
希望改用新版本的 ts 模块,但不清楚为何两者返回的 profile 数据差异如此之大,恳请指点。
1. 确保 loadUserInfo 参数全局生效
oidc-client-ts 与 oidc-client-js 的 loadUserInfo 默认值可能不同,需在主配置和回调页配置中都显式设置 loadUserInfo: true。回调页的 UserManager 处理授权响应时,同样需要触发 UserInfo 端点请求来获取完整用户数据。
2. 补全回调页的关键配置参数
当前回调页的 UserManager 缺少 response_type 和 scope,这会导致处理授权响应时无法正确触发后续流程。补全后配置如下:
{ authority: "https://localhost:3000", response_mode: "query", client_id: "js", redirect_uri: "https://localhost:3001/callback.html", response_type: "code", scope: "openid profile IdentityServerApi colour", loadUserInfo: true }
3. 验证 UserInfo 端点的返回内容
直接调用 IdentityServer 的 UserInfo 端点(GET {authority}/connect/userinfo,携带有效 Access Token),确认返回数据是否包含缺失的 name、favorite_colour 等字段。如果端点返回完整数据,但 ts 模块未合并,需检查 filterProtocolClaims 参数是否过滤了非标准 claims。
4. 检查授权请求的 Scope 传递情况
通过浏览器开发者工具查看授权跳转的 URL,确认 scope 参数确实包含 profile 和 colour。若 Scope 传递不完整,IdentityServer 不会返回对应的自定义 claims。
5. 注意两个库的行为差异
oidc-client-ts 作为 oidc-client-js 的重构版本,部分默认行为有变更:
- 部分版本中
loadUserInfo默认值为false,而旧版 js 可能默认true; - ts 版本中
user.profile可能仅包含 ID Token 中的 claims,UserInfo 端点返回的数据需从user.userInfo属性单独获取,而非自动合并到 profile。
内容的提问来源于stack exchange,提问作者Joseph Hutton

